โ† All LCA Flashcard Decks

System Security & Firewall Management Flashcards

7 cards from real LCA practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 System Security & Firewall Management flashcards as text
  1. Which firewalld zone is most appropriate for a highly trusted internal network interface?

    Answer: trusted

    The 'trusted' zone in firewalld accepts all connections and is designed for fully trusted networks.

  2. What command permanently adds HTTP service to the active firewalld zone?

    Answer: firewall-cmd --permanent --add-service=http

    The --permanent flag ensures the rule persists across reboots; --reload is then needed to apply it.

  3. Which SELinux command is used to change a file's security context permanently?

    Answer: semanage fcontext

    semanage fcontext adds a persistent policy rule, while chcon only changes the context temporarily.

  4. What does the 'nmap -sS' scan type perform?

    Answer: TCP SYN (stealth) scan

    A SYN scan sends SYN packets and never completes the handshake, making it faster and less detectable than a full connect scan.

  5. Which file configures system-wide PAM password quality requirements on RHEL-based systems?

    Answer: /etc/security/pwquality.conf

    pwquality.conf is read by the pam_pwquality module to enforce password complexity rules.

  6. Which iptables target silently drops packets without sending any response?

    Answer: DROP

    DROP silently discards the packet, whereas REJECT sends an ICMP error back to the sender.

  7. What is the purpose of the /etc/hosts.deny file in TCP Wrappers?

    Answer: Denies access to specified hosts for wrapped services

    TCP Wrappers checks /etc/hosts.allow first, then /etc/hosts.deny to determine whether to permit a connection.